February 2012
Intermediate to advanced
800 pages
23h 55m
English
Analyze the malware found in the file Lab12-01.exe and Lab12-01.dll. Make sure that these files are in the same directory when performing the analysis.
Q: | 1. What happens when you run the malware executable? |
Q: | 2. What process is being injected? |
Q: | 3. How can you make the malware stop the pop-ups? |
Q: | 4. How does this malware operate? |
Analyze the malware found in the file Lab12-02.exe.
Q: | 1. What is the purpose of this program? |
Q: | 2. How does the launcher program hide execution? |
Q: | 3. Where is the malicious payload stored? |
Q: | 4. How is the malicious payload protected? |
Q: | 5. How are strings protected? |
Analyze the malware extracted during the analysis of Lab 12-2 Solutions, or use the file Lab12-03.exe.
Q: | 1. What ... |